Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors atomsilo

Description

AtomSilo is a double-extortion ransomware group that emerged in September 2021, exploiting the Atlassian Confluence vulnerability (CVE-2021-26084) for initial access and demanding ransoms up to $1 million, attributed to the Chinese state-linked threat actor BRONZE STARLIGHT. Known victims: 5 1 ransom note(s) on file

Goals & Targeting

Objectives

Ransomware
Financial Gain

AI Analysis

· 1 week ago

Executive Summary

AtomSilo is a medium-sophistication criminal threat actor specializing in ransomware operations with a primary focus on financial gain. Known for double-extortion tactics, AtomSilo uses initial access via the Atlassian Confluence vulnerability (CVE-2021-26084) and has targeted sectors such as healthcare and education. The group is suspected to be linked to BRONZE STARLIGHT, a Chinese state-linked actor, and has been active since December 2021.

Goals & Targeting

AtomSilo targets sectors with sensitive data or less robust cybersecurity defenses, such as healthcare and education. The group seeks to maximize financial gains through double extortion campaigns, where victims are coerced into paying ransoms or face public shaming via leaked data. Their strategic focus appears to be on disrupting organizational operations while leveraging high-profile attacks to establish notoriety in the ransomware landscape. Typical victims include mid-to-large sized organizations with accessible network entry points.

Enhanced Description

AtomSilo is a double-extortion ransomware group that emerged in late 2021, leveraging the Atlassian Confluence vulnerability (CVE-2021-26084) for initial network access. The group operates with a clear focus on financial gain, employing double extortion tactics where victims are threatened with data leaks if they fail to pay the ransom. AtomSilo's targeting patterns suggest a preference for sectors like healthcare and education, possibly due to their access to sensitive data or weaker defensive postures. The group has been linked to BRONZE STARLIGHT, a Chinese state-linked threat actor, further complicating its operational landscape. Known victims include organizations in North America and Europe, with one notable incident involving the deployment of high ransom demands (up to $1 million). AtomSilo's campaign patterns indicate a focus on disrupting operations while maximizing financial gain through sophisticated extortion schemes.

Key Capabilities

  • Exploitation of Atlassian Confluence vulnerabilities (CVE-2021-26084)
  • Double extortion ransomware deployment
  • Spear-phishing campaigns for initial access
  • Use of custom or known ransomware tools
  • Data exfiltration and public leak threats
  • Fast-flux command and control infrastructure

MITRE ATT&CK Tactics

Initial Access
Data Exfiltration
Defense Evasion
Credential Access

ATT&CK Techniques

T1078.004
T1566.002
T1055.003
T1010.001

Software / Tooling

Cobalt Strike (presumed)
Custom ransomware
Phishing tools
C2 infrastructure

Campaigns & Victims

AtomSilo's campaigns typically involve phishing emails, exploitation of CVE-2021-26084, and deployment of ransomware with double extortion demands. The group appears to target organizations in the healthcare and education sectors, as seen in a notable attack on a US healthcare system in June 2022. Campaigns often include threats of data leaks to pressure victims into payment. Notable operations include high-profile attacks on educational institutions and healthcare providers, with a focus on maximizing financial gain through large ransom demands.

IOC Patterns

  • Spear-phishing emails containing malicious links or attachments
  • C2 communication over fast-flux DNS domains
  • Web shell activity related to CVE-2021-26084
  • Ransomware-related encryption patterns in file systems
  • High volumes of outbound network traffic post-compromise
  • Presence of encrypted files with specific extension patterns

Recommended Actions

  • Patch all Atlassian Confluence instances and related software promptly.
  • Implement multi-factor authentication for remote access tools.
  • Monitor for unusual network traffic, especially DNS queries to unknown domains.
  • Regularly back up critical systems and store backups offline.
  • Educate employees on phishing email tactics and suspicious emails.
  • Segment networks to limit lateral movement potential.
  • Deploy endpoint detection and response (EDR) solutions.

Suggested Tags

APT
ransomware
espionage
healthcare-sector
education-sector
double-extortion

Confidence Assessment

Moderate confidence in AtomSilo's profile, with additional context needed on specific tools and exact targeting criteria. Further analysis of campaign TTPs and technical indicators is required to fully understand the group's capabilities.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
APT
ransomware
espionage
healthcare-sector
education-sector
double-extortion

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Confidence
80%
First Seen
Dec 21, 2021
Last Seen
Feb 24, 2026
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.